The XMLHttpRequest object in Mozilla... CVE-2005-4874

4.3 AV AC AU C I A
发布: 2005-12-31
修订: 2017-08-08

The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a "Max-Forwards: 0" header or (2) arbitrary local passwords on the web server that hosts this object.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息